Description

The Ubisoft Corporate Security Program maintains a trusted, public channel for reporting security issues that affect Ubisoft’s corporate assets — for example, internet‑facing services, corporate web apps and APIs, partner/employee portals, official desktop and mobile applications, and related cloud/storage/CDN infrastructure. Our aim is to work with the security community to find and fix vulnerabilities before they impact employees, partners, customers, or corporate data. We welcome responsible, non‑disruptive testing and clear reports that include concise, reproducible steps and only the evidence necessary to demonstrate impact. Do not perform actions that harm availability, privacy, or other users; avoid extracting large data sets or accessing accounts you do not own. Do not attempt social engineering, physical intrusion, destructive testing (including DoS/DDoS), or any activity that could violate laws or program rules. When submitting an issue, include enough context and a proof‑of‑concept to enable replication while minimizing exposure of sensitive data. Our Security team will acknowledge submissions, triage them promptly, communicate status updates, and provide recognition in accordance with program guidelines. To report a vulnerability, please submit via Intigriti so our team can investigate and remediate the issue quickly. Note: This program covers corporate assets only. For in‑game vulnerabilities, please use the separate channels designated for game reports.

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 2
0
500
1,250
2,000
2,500
Tier 2
Up to €2,500
All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.